A zero-knowledge, client-side encrypted virtual filesystem for cloud storage.
Try the live demo → - AES-256-GCM encryption running entirely in your browser, no install required.
Cryptbox 2.0 encrypts your files before they ever touch a sync folder like Dropbox or iCloud. The cloud provider only ever sees ciphertext, encrypted metadata, and RSA-signed integrity proofs - never a plaintext byte, and never your encryption keys. It's a from-scratch re-engineering of the original MIT Cryptobox project, rebuilt around modern authenticated encryption, RSA-based secure sharing, digital signatures, and a real web dashboard.
This repository is the reference implementation behind our paper published at IEEE ICSFT 2026 (see Citation).
- Features
- How it's built
- Security model
- Quick start
- Using it
- Project structure
- Testing
- Live demo vs. the full project
- Roadmap
- Citation
- License
- AES-256-GCM authenticated encryption for every file - confidentiality and tamper-detection in one primitive.
- PBKDF2-HMAC-SHA256 key derivation (100,000 iterations, random 16-byte salt per file) - a password never gets used as a key directly.
- RSA key management for signing and secure sharing, with private keys
written to disk at mode
0600. - RSA-PSS/SHA-256 digital signatures on every encrypted file, verified automatically on open.
- Secure multi-user sharing - a file's password is RSA-wrapped per
recipient into a portable
.jsonbundle. The plaintext password never crosses the network. - Encrypted metadata - original filenames, MIME types, and timestamps are encrypted separately from file contents, so directory listings on the cloud side leak nothing.
- FUSE-mounted virtual drive - once mounted, encrypted storage behaves like an ordinary folder; files decrypt on open and re-encrypt on save.
- Web dashboard (Flask) - encrypt, decrypt, share, sign-verify, and manage keys from a browser, no FUSE mount required.
- CLI (Click) -
init,mount,unmount,status,export-key,share,receive.
User
├── CLI (Click) ──┐
└── Web Dashboard ─┼──► Cryptographic Core
│ FileEncryptor (AES-256-GCM)
│ RSAKeyManager (RSA-2048)
│ DigitalSignature (RSA-PSS/SHA-256)
│ SecureSharing / KeyExchange
│ MetadataManager (encrypted filenames/attrs)
│ ConfigManager (passwords, mount point, prefs)
▼
CryptboxFS (FUSE layer)
transparent encrypt-on-write / decrypt-on-open
│
▼
Local encrypted storage (*.enc, *.sig)
│
▼
Cloud sync (Dropbox / iCloud / etc.) - ciphertext only
Full module-by-module breakdown, including the exact data flow for
encrypting and sharing a file, is in
docs/architecture.md.
| Property | Mechanism |
|---|---|
| File confidentiality | AES-256-GCM, 256-bit key, 96-bit nonce, 128-bit tag |
| Key derivation | PBKDF2-HMAC-SHA256, 100,000 iterations, per-file random salt |
| File integrity | AES-GCM auth tag + RSA-PSS/SHA-256 signature over ciphertext |
| Password sharing | RSA-2048-OAEP, wrapped per recipient, zero plaintext transit |
| Metadata privacy | AES-256-GCM over filename/MIME/timestamp JSON |
| Key-at-rest protection | Private key file permissions forced to 0600 |
Threat model, verified guarantees, and - just as important - the honest list
of current limitations (RSA-2048 vs. the paper's RSA-4096, no forward
secrecy, TOFU-only key trust) are documented in
docs/security_analysis.md.
git clone https://github.com/krishnavarma024/cryptbox-2.0.git
cd cryptbox-2.0
python3 -m venv venv && source venv/bin/activate
pip install -r requirements.txt
python gui/dashboard.py
# -> open http://localhost:5000That's the whole setup for the web dashboard - no FUSE, no system packages.
FUSE mounting (cryptbox mount) needs macFUSE (macOS) or libfuse2 (Linux)
installed separately; see docs/user_guide.md.
cryptbox init # generate RSA keys + set password
cryptbox status # check config / mount state
cryptbox export-key alice.json --name Alice --email alice@example.com
cryptbox share secret.txt.enc bob_public_key.json -o secret.bundle.json
cryptbox receive secret.bundle.json secret.txt.enc
cryptbox mount # requires FUSEA full walkthrough of both the dashboard and the CLI - including a
troubleshooting table for the classic "forgot how to run it" moment - is in
docs/user_guide.md.
cryptbox/ Core package: encryption, keys, signatures, sharing,
metadata, config, FUSE filesystem, CLI entry point
gui/ Flask web dashboard + template
utils/ Crypto primitives (PBKDF2/SHA-256) + file helpers
tests/ 35 pytest tests across every module
docs/ architecture.md, security_analysis.md, user_guide.md
web-demo/ Static, client-side AES-256-GCM demo (GitHub Pages)
demo_presentation.py Scripted end-to-end walkthrough used for the paper's figures
pytest -v35 tests, ~10s: crypto primitives, AES-256-GCM round-trips and tamper
detection, RSA key management, digital signatures, encrypted metadata, the
FUSE Operations layer (skipped gracefully if libfuse isn't present), and
the full multi-user secure-sharing workflow. CI runs the whole suite on
Python 3.10-3.12 and additionally boots the Flask dashboard and hits its API
end to end - see .github/workflows/ci.yml.
The GitHub Pages demo is a
pure client-side reimplementation of just the AES-256-GCM file encryption
(cryptbox/encryption.py), using the browser's native crypto.subtle -
nothing is uploaded anywhere. It uses the exact same container format
(salt[16] || nonce[12] || tag[16] || ciphertext), so a file encrypted in the
browser decrypts correctly with the real Python FileEncryptor and vice
versa - verified with a Node.js/Python interop test during development.
It intentionally doesn't include RSA key management, secure sharing, signatures, or the FUSE mount. For those, clone the repo and run the real thing (see Quick start).
- Default to RSA-4096 (matching the published paper); keep RSA-2048 as an opt-in for speed.
- Random per-installation salt for metadata key derivation.
- Optional Argon2id path for password-based key derivation.
- Lightweight key-trust UX (fingerprint display, TOFU change warnings) for secure sharing.
If you reference this work, please cite:
K. Varma, B. Teja, and S. G, "Cryptbox 2.0: A Secure Client-Side Encrypted File Storage and Sharing Framework," presented at the IEEE International Conference on Smart Systems and Future Technologies (ICSFT) 2026.
@inproceedings{varma2026cryptbox,
title = {Cryptbox 2.0: A Secure Client-Side Encrypted File Storage and Sharing Framework},
author = {Varma, Krishna and Teja, Bharath and G, Sreeraag},
booktitle = {Proceedings of the IEEE International Conference on Smart Systems and Future Technologies (ICSFT)},
year = {2026},
publisher = {IEEE}
}MIT - see LICENSE.
Krishna Varma - krishnavarma024@gmail.com Department of Computer Science and Engineering, Amrita School of Computing, Bengaluru, Amrita Vishwa Vidyapeetham.